sk Skill · PentesterFlow
jwt
JWT attack playbook — algorithm confusion (alg=none, HS/RS confusion), kid path traversal/SQLi, jku/x5u SSRF, weak HS256 cracking, and embedded JWK trickery. Use when the target uses JWTs for auth (header.payload.signature).
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 2
- Connections
- 4
pythonbashTypeScript
- Host repository
- PentesterFlow/agent
- Allowed tools
- http, shell, read_payloads, file_write
- Host stars
- 1,360
- Host language
- TypeScript